Data security incident correlation and dissemination system and method
Summary by NHIP
Correlated incident notification system
The system aggregates incident data from multiple organizations to generate correlated records and threat intelligence. It notifies affected entities when a given number of same-type correlations relate to given incident information to facilitate mitigation.
Claim Score by NHIP
Abstract
A data security incident correlation and dissemination system and method is disclosed. In an exemplary implementation of the system, a service provider of a managed security service receives incident information regarding data security incidents at different business organizations of the security service. One or more incident managers operated by different organizations send incident information, and a server system within the service provider's network creates aggregated data from the incident information received from the incident managers. The server system analyzes the aggregated data to create correlated incident records that include incident information from related data security incidents at the different organizations, and provides threat intelligence data based on the correlated incident records for the organizations. In embodiments, the server system can “push” threat intelligence data to the organizations, or the organizations can request the threat intelligence data from the server system.

Term
9.8 yearsleft in the term
Expires 28 July 2036, including 213 days of term adjustment.
- Priority and filed
- Granted
- Today
- Expires
20 claims: 2 independent, 18 dependent
- 1A data security incident correlation and dissemination system, the system comprising:a server system that creates aggregated data from incident information received from a set of incident managers at least two of which are operated by different organizations, the server system including an analysis engine that analyzes the aggregated data to create correlated incident records that include incident information from data security incidents at the different organizations that have been determined by the analysis engine to be related, at least one correlated incident record being uniquely associated with a correlation found by the analysis engine and including a nature and relative strength of the correlation, and that provides threat intelligence data to the organizations based on the correlated incident records;wherein upon detecting that a given number of correlations of a same type within the correlated incident records has occurred and relate to given incident information, the server system is further operative to notify the different organizations that have been affected by the given incident to facilitate a mitigation effort.
- 11Broadest claimClaim Score 52, average(NHIP)A data security dissemination method, the method comprising:receiving incident information from a set of incident managers at least two of which are operated by different organizations;and creating aggregated data from the incident information received from the incident managers, analyzing the aggregated data using an analysis engine to create correlated incident records that include incident information from data security incidents at the different organizations that have been determined by the analysis engine to be related, at least one correlated incident record being uniquely associated with a correlation found by the analysis engine and including a nature and relative strength of the correlation, and providing threat intelligence data based on the correlated incident records to the organizations;and responsive to detecting that a given number of correlations of a same type within the correlated incident records has occurred and relate to given incident information, notifying the different organizations that have been affected by the given incident to facilitate a mitigation effort.
Independent claims2
72 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
Data security incidents pose a major operational and financial risk for organizations such as businesses and governments. In examples, data security incidents include loss of physical assets, such as a company laptop computer that contains company-confidential information and cyber attacks launched against systems and assets of a company's enterprise network. Any delays when responding to data security incidents such as cyber attacks increases the potential for damage to the organizations and loss of valuable data.
Cyber attacks target security vulnerabilities of computers within an organization's enterprise network. In examples, security vulnerabilities can exist in operating systems of the computers, within software executed by the operating systems, and within data networking systems of the enterprise network. Examples of cyber attacks include actions designed to disrupt normal business operations and intrusion attempts to obtain unauthorized access to the computer systems.
Increasingly, organizations are deploying incident manager (IM) applications to track responses to data security incidents such as cyber attacks.
SUMMARY OF THE INVENTION
Current incident manager (IM) applications will typically manage responses to data security incidents within specific organizations. Though data security incidents of the same type often occur across multiple organizations, current incident manager applications typically cannot disseminate or share responses to data security incidents between organizations such as different business entities. For example, one organization's responses to a Denial of Service (DoS) cyber attack launched in the recent past against a well-known TCP port cannot be applied to a similar cyber attack currently occurring within the enterprise network of a different organization. The effort associated with responding to the data security incident is effectively duplicated within the incident managers, which is inefficient.
The inability for incident managers of organizations to share responses to common data security incidents across different organizations wastes an opportunity to limit the response time and effectiveness of responding to future data security incidents of the same type, in one example. Organizations that are part of the same business sector are often targeted by the same cyber attacks. Sharing this information between organizations would potentially decrease the response time for responding to future cyber attacks for other organizations. An incident management system that enables incident manager applications of different organizations to share incident information of data security incidents and responses to the incidents can also be referred to as a data security incident correlation and dissemination system.
In general, according to one aspect, the invention features a data security incident correlation and/or dissemination system. The system comprises one or more incident managers operated by different organizations and a server system. The server system creates aggregated data from incident information received from the incident managers, analyzes the aggregated data to create correlated incident records that include incident information from related data security incidents at the different organizations, and provides threat intelligence data to the organizations based on the correlated incident records.
Preferably, the server system determines trends among the incident information within the aggregated data, and includes the trends as trends data within the threat intelligence data that the server system sends to the organizations. The server system also anonymizes the threat intelligence data to remove information that identifies the organizations. Typically, the incident information received from the incident managers of the organizations includes the incident information from the data security incidents at the organizations. This may include findings of significance such as indicators of compromise (e.g. hashes of files used by the attacker in carrying out the attack or other) or information about tactics, techniques and tools used by the attackers, in examples.
The incident information received from the incident managers also includes incident response data that includes recommendations and remediation techniques created by the organizations in response to the data security incidents at the organizations.
In one embodiment, the server system provides threat intelligence data to the organizations based on the correlated incident records by sending the threat intelligence data to the incident managers upon request by the incident managers.
The incident information received from the incident managers is typically pushed from the incident managers of the organizations.
The server system can receive sharing and usage information sent from the incident managers of the organizations that specifies rules for sharing the incident information with other organizations. The correlated incident records preferably include metadata that includes the sharing and usage information sent from the incident managers of the organizations.
In one example, the incident information can be used to identify organizations experiencing a similar threat, and to offer a mechanism to bring these organizations together to share information and collaborate on a response to the data security incidents.
According to a preferred embodiment, the server system includes predetermined rules and an analysis engine that compares the threat intelligence data to the predetermined rules, and wherein in response to events within the threat intelligence data matching the predetermined rules, the analysis engine sends the threat intelligence data associated with the matching events to the incident managers of the organizations.
In general, according to another aspect, the invention features a data security dissemination method. The method comprises one or more incident managers operated by different organizations sending incident information, and a server system creating aggregated data from the incident information received from the incident managers. The server system also analyzes the aggregated data to create correlated incident records that include incident information from related data security incidents at the different organizations, and provides threat intelligence data based on the correlated incident records for the organizations.
The above and other features of the invention including various novel details of construction and combinations of parts, and other advantages, will now be more particularly described with reference to the accompanying drawings and pointed out in the claims. It will be understood that the particular method and device embodying the invention are shown by way of illustration and not as a limitation of the invention. The principles and features of this invention may be employed in various and numerous embodiments without departing from the scope of the invention.
BRIEF DESCRIPTION OF THE DRAWINGS
In the accompanying drawings, reference characters refer to the same parts throughout the different views. The drawings are not necessarily to scale; emphasis has instead been placed upon illustrating the principles of the invention. Of the drawings:
<figref idref="DRAWINGS">FIG. 1</figref> shows a block diagram of an exemplary data security incident correlation and dissemination system that aggregates and correlates incident information concerning data security incidents from enterprise networks of selected organizations;
<figref idref="DRAWINGS">FIG. 2A</figref> is a flow chart that describes a method of operation of a server system of the data security incident correlation and dissemination system for responding to registration requests from incident managers of the organizations;
<figref idref="DRAWINGS">FIG. 2B</figref> is a flow chart that describes a method of operation of a preferred embodiment of the server system for creating aggregated data from incident information “pushed” from incident managers, and where the method also analyzes the aggregated data, derives and stores threat intelligence data from the analyzed aggregated data, and provides the threat intelligence data to the organizations via their incident managers;
<figref idref="DRAWINGS">FIG. 3</figref> and <figref idref="DRAWINGS">FIG. 4</figref> are flow charts that provides more detail for the flow chart of <figref idref="DRAWINGS">FIG. 2B</figref>; and
<figref idref="DRAWINGS">FIGS. 5A and 5B</figref> are flow charts that show an alternate embodiment of the server system, with <figref idref="DRAWINGS">FIG. 5A</figref> showing how the server system responds to a request from an incident manager of an organization for threat intelligence data associated with a specific incident, and with <figref idref="DRAWINGS">FIG. 5B</figref> showing how the server system responds to a request from an incident manager of an organization for all trends data of the threat intelligence data over a specific time period.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
The invention now will be described more fully hereinafter with reference to the accompanying drawings, in which illustrative embodiments of the invention are shown. This invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
As used herein, the term “and/or” includes any and all combinations of one or more of the associated listed items. Further, the singular forms and the articles “a”, “an” and “the” are intended to include the plural forms as well, unless expressly stated otherwise. It will be further understood that the terms: includes, comprises, including and/or comprising, when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and/or groups thereof. Further, it will be understood that when an element, including component or subsystem, is referred to and/or shown as being connected or coupled to another element, it can be directly connected or coupled to the other element or intervening elements may be present.
<figref idref="DRAWINGS">FIG. 1</figref> shows an exemplary implementation of a data security incident correlation and dissemination system <b>10</b>. The system <b>10</b> includes a service provider network <b>132</b> of a service provider that provides a managed security service to one or more business organizations. The service provider network <b>132</b> communicates over a network cloud <b>26</b> with one or more enterprise networks <b>130</b> of the organizations. In one example, the service provider network <b>132</b> and one or more of the organizations are all owned or operated by different business entities.
Enterprise networks <b>130</b>-<b>1</b> through <b>130</b>-<b>4</b> of exemplary organizations ACME Company, BigCorp, CamCorp, and DataCorp are shown, respectively. Firewalls <b>36</b>-<b>1</b> through <b>36</b>-<b>4</b> enable communications between corporate networks <b>70</b>-<b>1</b> through <b>70</b>-<b>4</b> of enterprise networks <b>130</b>-<b>1</b> through <b>130</b>-<b>4</b>, respectively.
The service provider network <b>132</b> includes a server system <b>190</b> and a datastore <b>135</b>. Also shown are one or more threat information sources (TIS) <b>40</b>. Examples include malware, geolocation, and domain name threat information sources <b>40</b>-<b>1</b> through <b>40</b>-<b>3</b>, respectively.
The server system <b>190</b> executes queries associated with data security incidents against one or more threat information sources (TIS) <b>40</b> to obtain more information about the incidents. The server system <b>190</b> saves information based on the data security incidents to the datastore <b>135</b>. In one example, the server system <b>190</b> is an expert system that includes predictive technologies such as artificial intelligence and machine learning capabilities.
The server system <b>190</b> includes an application server <b>180</b>-<b>1</b>, IM registration data <b>94</b> and an analysis engine <b>176</b>. The server system <b>190</b> also includes predetermined rules <b>177</b>, aggregated data <b>46</b> and a notifier <b>96</b>.
Each organization operates one or more incident managers <b>102</b> that manage data security incidents detected within the enterprise networks <b>130</b> of the organizations. In one implementation, the incident manager(s) <b>102</b> are physically located within the service provider network <b>132</b> and are implemented as SaaS applications hosted by application server <b>180</b>-<b>1</b>. In another implementation, the incident manager(s) (<b>102</b>-<b>1</b>) are physically located within the respective corporate networks <b>70</b>-<b>1</b>. In the illustrated example, incident managers <b>102</b>-<b>2</b> and <b>102</b>-<b>3</b> manage data security incidents for organization BigCorp's Finance and Manufacturing subnets <b>72</b> of BigCorp's enterprise network <b>130</b>-<b>2</b>, and incident manager <b>102</b>-<b>4</b> manages data security incidents for organization DataCorp's enterprise network <b>130</b>-<b>4</b>. In another implementation, the incident managers <b>102</b> are included within the enterprise networks <b>130</b> of the organizations themselves. For example, incident manager <b>102</b>-<b>1</b> for ACME Company is hosted by application server <b>180</b>-<b>2</b> within ACME Company's enterprise network <b>130</b>-<b>1</b> and incident manager <b>102</b>-<b>5</b> for CamCorp is hosted by application server <b>180</b>-<b>3</b> within CamCorp's enterprise network <b>130</b>-<b>3</b>.
The components within ACME Company's enterprise network <b>130</b>-<b>1</b> and that of its incident manager <b>102</b>-<b>1</b> are a typical example of components within organizations that communicate with the service provider network <b>132</b>. The enterprise network <b>130</b>-<b>1</b> for ACME Company includes exemplary devices, software and systems that communicate over a corporate network <b>70</b> and among one or more subnetworks <b>72</b>. The subnetworks <b>72</b> are segmented from the corporate network <b>70</b> via a router <b>34</b>. Devices include firewall <b>36</b>-<b>1</b>, router <b>34</b>, web server <b>160</b>, and a configuration server <b>103</b>. The web server <b>160</b> includes a browser <b>150</b>, which incident response team (IRT) <b>172</b> personnel utilize to manage and configure the devices and the incident manager <b>102</b>-<b>1</b>.
ACME Company's incident manager <b>102</b>-<b>1</b> includes a knowledge base <b>122</b> and a messaging system <b>62</b>. The knowledge base <b>122</b> stores information associated with data security incidents detected within ACME Company's enterprise network <b>130</b>-<b>1</b>. The knowledge base <b>122</b> includes sharing and usage information <b>144</b>-<b>1</b>, action conditions <b>44</b>, and incident information <b>59</b>. The incident information <b>59</b> includes details of the incidents such as incident objects <b>41</b>, incident artifacts (IAs) <b>120</b> and notes <b>121</b>. The incident information <b>59</b> also includes recommended actions and remediation techniques published by the organizations in response to specific incidents, also known as incident response data <b>92</b>.
When ACME Company's incident manager <b>102</b>-<b>1</b> detects that incident information <b>59</b> has satisfied/met conditions of the action conditions <b>44</b>, the incident manager <b>102</b>-<b>1</b> includes the incident information <b>59</b> in messages. The incident manager <b>102</b>-<b>1</b> then sends the messages to its messaging system <b>62</b>. The messages can include incident information <b>59</b> and sharing and usage information <b>144</b>-<b>1</b>, in examples. The messaging system <b>62</b> is implemented as a Java Messaging Service (JMS), in one example. The messaging system <b>62</b> can either “push” the messages over the network <b>26</b> to the server system <b>190</b>, or alternatively, the server system <b>190</b> can poll or request the messaging systems <b>62</b> of each of the incident managers <b>102</b> for the messages, in examples.
When ACME Company's incident manager <b>102</b>-<b>1</b> includes incident information <b>59</b> in the messages sent to the server system <b>102</b>, the incident manager <b>102</b>-<b>1</b> can additionally include sharing and usage information <b>144</b>-<b>1</b> in the messages. The sharing and usage information <b>144</b>-<b>1</b> is associated with the incident information <b>59</b> and indicates whether the incident information <b>59</b> can be shared with other organizations. The sharing and usage information <b>144</b>-<b>1</b> specifies rules and/or policies (e.g. access control lists) for disseminating the incident information <b>59</b> among the organizations. The server system <b>190</b> receives the messages from the incident managers <b>102</b> of the organizations, and uses the sharing and usage information <b>144</b> in the received messages as the basis for subsequent sharing and usage policy in data that the server system <b>190</b> creates in response to receiving the messages.
The notifier <b>96</b> receives the messages from the incident managers <b>102</b> and creates aggregated data <b>46</b> from the messages. Each record of aggregated data <b>46</b> includes incident information <b>59</b> and optionally sharing and usage information <b>144</b>-<b>2</b>. The analysis engine <b>176</b> can also process the messages received by the notifier <b>96</b> and create IM registration data <b>94</b> that includes sharing and usage information <b>144</b>-<b>3</b>.
The server system <b>190</b> stores threat intelligence data <b>54</b> to datastore <b>135</b>. Threat intelligence data <b>54</b> includes correlated incident records <b>58</b> and trends data <b>50</b>. In a preferred embodiment, the server system <b>190</b> via its notifier <b>96</b> receives incident information <b>59</b> and sharing and usage information <b>144</b> that are pushed from each of the incident managers <b>102</b>. In an alternate implementation, the server system <b>190</b> via its notifier <b>96</b> can request or poll the incident managers <b>102</b> for the incident information <b>59</b> and sharing and usage information <b>144</b>.
The analysis engine <b>176</b> analyzes the records of aggregated data <b>46</b> to determine correlations or similarities among the records of aggregated data <b>46</b>. For each correlation found, the analysis engine <b>176</b> creates a separate correlated incident record <b>58</b> that includes the incident information <b>59</b> from the aggregated data <b>46</b> records determined to have correlations or similarities. The sharing and usage information <b>144</b>-<b>5</b> associated with the incident information <b>59</b> is stored within metadata <b>56</b> of each correlated incident record <b>58</b>.
The analysis engine <b>176</b> then determines trends among the incident information <b>59</b> within the correlated incident records <b>58</b>, and includes the trends as trends data <b>50</b> within the threat intelligence data. If the correlated incident records <b>58</b> include sharing and usage information <b>144</b>-<b>5</b> in its metadata <b>56</b>, the analysis engine includes the sharing and usage information <b>144</b>-<b>6</b> within the trends data <b>50</b>.
In examples, the capabilities provided by the server system <b>190</b> can be implemented by a single physical computer system or be distributed across multiple physical or virtual computer systems. In the former example, the server system <b>190</b> is a single physical computer system located within the service provider network <b>132</b> of the service provider. In the latter example, the server system <b>190</b> includes multiple physical computer systems located within the service provider network <b>132</b> and one or more virtual computer systems, where the virtual computer systems are third party cloud based services that the service provider accesses via the network cloud <b>26</b>. In this way, processing associated with the aggregation, correlation, and dissemination of information based on incident information <b>59</b> of data security incidents can be shared or distributed across the one or more physical or virtual computer systems of the notional server system <b>190</b>.
<figref idref="DRAWINGS">FIG. 2A</figref> shows a registration method of the server system <b>190</b>. The registration specifies the scope of the information sharing to which each organization allows.
In step <b>196</b>, the notifier <b>96</b> receives a registration request from one or more incident managers <b>102</b>, where the registration request specifies the organizations that each incident manager will share its incident information <b>59</b> with, and where the registration request also specifies the scope of the information usage and sharing between the organizations. In step <b>198</b>, the notifier <b>96</b> stores the information in the registration request to IM registration data <b>94</b> of the server system <b>190</b>.
<figref idref="DRAWINGS">FIG. 2B</figref> describes a method of operation of the server system for creating aggregated data <b>46</b> for incidents and creating threat intelligence data <b>54</b>.
In step <b>202</b>, the server system <b>190</b> waits for the next message from an incident manager <b>102</b> within an enterprise network <b>130</b>. In step <b>204</b>, the Notifier <b>96</b> receives incident information <b>59</b> (e.g. incident objects <b>41</b>, incident artifacts <b>120</b>, notes <b>121</b>, incident response data <b>92</b>) associated with data security incidents included within messages “pushed” from incident managers <b>102</b> of organizations, where the messages optionally include sharing and usage information <b>144</b> for the incident information <b>59</b>.
According to step <b>206</b>, Notifier <b>96</b> formats the received incident information <b>59</b> within the messages into aggregated data <b>46</b>, where the aggregated data <b>46</b> additionally includes optional sharing and usage information <b>144</b> for the incident information <b>59</b>.
In step <b>208</b>, the notifier <b>96</b> tests if any sharing and usage information <b>144</b> was included within the messages sent by the incident managers <b>102</b>. If the result of this test is true, the method transitions to step <b>214</b>. Otherwise, the method transitions to step <b>210</b>.
In step <b>210</b>, the notifier <b>96</b> executes a lookup within the IM registration data <b>94</b> to determine sharing and usage information <b>144</b>-<b>3</b> for the incident manager <b>102</b> sending the message. In step <b>212</b>, the notifier <b>96</b> tests if an entry for the current incident manager <b>102</b> is found within the IM registration data <b>94</b>. If no entry is found, the method transitions back to step <b>202</b> to wait for more messages sent from incident managers <b>102</b>. Otherwise, the method transitions to step <b>214</b>.
In step <b>214</b>, the analysis engine <b>176</b> analyzes the aggregated data <b>46</b>, derives threat intelligence data <b>54</b> from the analysis, and stores anonymized threat intelligence data <b>54</b> to a datastore <b>135</b>, where the threat intelligence data <b>54</b> is subsequently available upon request by incident managers <b>102</b> of different member organizations.
Upon completion of step <b>214</b>, the method transitions to step <b>216</b>. In step <b>216</b>, in response to events within the threat intelligence data <b>54</b> matching predetermined rules <b>177</b>, the analysis engine sends threat intelligence data <b>54</b> associated with the matching events to one or more incident managers <b>102</b> of the organizations.
<figref idref="DRAWINGS">FIG. 3</figref> is a flow chart that provides more detail for step <b>214</b> of <figref idref="DRAWINGS">FIG. 2B</figref>.
In step <b>302</b>, the analysis engine <b>176</b> analyzes the incident information <b>59</b> of the aggregated data <b>46</b> to determine trends among the incident information <b>59</b>. The analysis engine <b>176</b> anonymizes the determined trends, and stores the determined trends in conjunction with the sharing and usage information <b>144</b> to trends data <b>50</b> of the threat intelligence data <b>54</b> within the datastore <b>135</b>. Preferably, the trends data <b>50</b> is stored in a format for providing to incident managers <b>102</b> upon request by the incident managers <b>102</b>.
In an alternate implementation, the analysis engine <b>176</b> can “push” the trends data <b>50</b> to the incident managers <b>102</b> of the organizations in an unsolicited fashion. Regardless of the method in which the trends data <b>50</b> is provided by the server system <b>190</b> to the incident managers <b>102</b>, the included sharing and usage information <b>144</b>-<b>6</b> specifies rules and/or the policies for disseminating the trends data <b>50</b> among the organizations.
According to step <b>306</b>, the analysis engine <b>176</b> searches the aggregated data <b>46</b> for correlations among the incident information <b>59</b> sent from one or more incident managers <b>102</b>, within the scope agreed upon by the organizations. This sharing scope is provided via either the sharing and information <b>144</b>-<b>2</b> included within the aggregated data <b>46</b> or within the sharing and information <b>144</b>-<b>3</b> included within the IM registration data <b>94</b>.
Then, in step <b>308</b>, the analysis engine <b>176</b> determines if any correlations between incident information <b>59</b> were found among the aggregated data <b>46</b>. If the result of this test is true, the method transitions to step <b>310</b> to continue processing. Otherwise, the method transitions to step <b>324</b> to end processing.
In step <b>310</b>, for each set of correlated incident information <b>59</b> found in the aggregated data <b>46</b>, the analysis engine <b>176</b> executes a lookup against the contents of any currently stored correlated incident records <b>58</b> in accordance with its usage and sharing information <b>144</b>-<b>5</b>. If any correlations were found between incident information <b>59</b> of aggregated data <b>46</b> and incident information <b>59</b> of any stored correlated incident records <b>58</b>, the method transitions to step <b>314</b>. Otherwise, the method transitions to step <b>318</b>.
In step <b>314</b>, the analysis engine <b>176</b> updates the correlated incident records <b>58</b> to include the correlated incident information determined from the aggregated data <b>46</b>. Then, in step <b>316</b>, the analysis engine <b>176</b> updates metadata <b>56</b> of the correlated incident records <b>58</b> with information regarding the nature and relative strength of the correlations and with any sharing and usage information <b>144</b>-<b>2</b> associated with the correlated incident information <b>59</b>.
In step <b>318</b>, the analysis engine <b>176</b> creates and stores one or more correlated incident records <b>58</b> that include the correlated incident information determined from the aggregated data <b>46</b>. In step <b>320</b>, the analysis engine <b>176</b> stores information regarding the nature and relative strength of the correlations and any sharing and usage information <b>144</b>-<b>2</b> associated with the correlated incident information <b>59</b> to correlation metadata <b>46</b> within the correlated incident records <b>58</b>.
Upon completion of both step <b>316</b> and <b>320</b>, the method transitions to step <b>322</b>.
In step <b>322</b>, the analysis engine <b>176</b> enriches the incident artifacts <b>120</b> and/or other incident information <b>59</b> of the correlated incident records <b>58</b> by executing lookups of incident artifact <b>120</b> details against other Threat Information Sources <b>40</b> (e.g. convert an IP address data resource of an incident artifact <b>120</b> to a DNS name via a lookup against the Domain Name TIS <b>40</b>-<b>3</b>, in one example). The analysis engine <b>176</b> can also append information obtained from the lookup against the threat information sources <b>40</b> to the incident artifacts <b>120</b> as another way of enriching the incident artifacts <b>120</b>.
Upon conclusion of step <b>322</b>, the threat intelligence data <b>54</b> is available for incident managers <b>102</b> to request. In examples, the incident managers <b>102</b> can request the entirety of the threat intelligence data <b>54</b>, or only subsets of the threat intelligence data <b>54</b>. In one example, multiple incident managers <b>102</b> request only the incident response data records <b>92</b> within the incident information <b>59</b> of the correlated incident records <b>58</b>. In the example, IRT <b>172</b> personnel can provide narrowing information in the request message such as the IP address of a “known bad” incident artifact <b>120</b>, with the intention of obtaining all incident response data <b>92</b> that other organizations published in response to incidents having the same IP address in their incident artifact(s) <b>120</b> and that the server system <b>190</b> included in one or more correlated incident records <b>58</b>. Preferably, the incident response data <b>92</b> is stored in a format for providing to incident managers <b>102</b> upon request by the incident managers <b>102</b>.
In response, the server system <b>190</b> sends associated incident response data <b>92</b> only to those incident managers <b>102</b> of the organizations that are authorized to view the incident response data <b>92</b>. The server system <b>190</b> uses the sharing and usage policy information <b>144</b>-<b>5</b> stored within the metadata <b>56</b> of the correlated incident record <b>58</b> from which each incident response data <b>192</b> was extracted to authorize the transaction. The method then transitions to step <b>324</b> to end processing.
<figref idref="DRAWINGS">FIG. 4</figref> is a flow chart that provides more detail for step <b>216</b> of <figref idref="DRAWINGS">FIG. 2B</figref>. The method of <figref idref="DRAWINGS">FIG. 4</figref> provides examples of how the analysis engine <b>176</b> of the server system <b>190</b> analyzes the threat intelligence data <b>54</b>, and “pushes” relevant portions of the threat intelligence data <b>54</b> matching predetermined rules <b>177</b> to the incident managers <b>102</b> of the organizations.
In step <b>402</b>, in accordance with the sharing and usage information <b>144</b>-<b>6</b> within the trends data <b>50</b>, the analysis engine <b>176</b> provides trends data <b>50</b> matching predetermined rules <b>177</b> to the incident managers <b>102</b>, e.g. “the most active artifact over the last 24 hrs is X”, or “organizations in the Finance sector are seeing a 27% increase in DDoS incidents over the last 6 hrs,” in examples.
According to step <b>404</b>, in accordance with the sharing and usage information <b>144</b>-<b>6</b> within the trends data <b>50</b>, the analysis engine <b>176</b> provides specific information to incident managers <b>102</b> associated with contents of correlated incident records <b>58</b> matching the predetermined rules <b>177</b>, e.g. that incident artifacts <b>120</b> of incident information <b>59</b> within correlated incident records <b>58</b> are “known bad” artifacts as well as providing suggested correlations. An example of a “known bad” incident artifact <b>120</b> is one that includes data resources such as IP addresses associated with known malware websites and sources.
In step <b>406</b>, in response to a predetermined rule <b>177</b> that specifies detecting increasing strength of correlations within the correlated incident records <b>58</b>, the analysis engine <b>176</b> enables users to view other attributes of strongly correlated incidents of the correlated incident records <b>58</b>, such as proposed remediation steps within the incident response data <b>92</b>, shared analyst notes <b>121</b>, attributed threat actors and other indicators of compromise, in examples.
According to step <b>408</b>, in response to a predetermined rule <b>177</b> that specifies detecting an increasing number of correlations of the same type within the correlated incident records <b>59</b>, the analysis engine <b>176</b> enables users to request to be connected to other individuals working those other incidents or to join pre-existing groups of individuals working on correlated incidents. For example, upon analyzing the incident information <b>59</b> in the correlated incident records <b>58</b>, the analysis engine <b>176</b> may determine that a predetermined rule <b>177</b> associated with an increasing number of “malware” incidents from the same source IP address is met. In response, the analysis engine <b>176</b> can send invitations to the organizations affected by the common malware correlated incident records <b>59</b> to participate in a phone conference to share their experiences and propose solutions.
Finally, in step <b>410</b>, the analysis engine <b>176</b> enables users of the system <b>10</b> to rate information from other correlated incidents (e.g. via “thumbs up or thumbs down”) which will affect their overall rating and save ratings to metadata <b>56</b> of the correlated incident records <b>59</b>. The analysis engine <b>176</b> enables this by sending a link (e.g. URL) for a ratings/voting website to the affected organizations, in another example.
<figref idref="DRAWINGS">FIG. 5A</figref> shows a method for an exemplary request issued by an incident manager <b>102</b> to the server system <b>190</b>, for threat intelligence data <b>54</b> matching a specific set of requested incident information <b>59</b>.
In step <b>502</b>, the notifier <b>96</b> of the server system <b>190</b> receives a query message from an incident manager <b>102</b>, where the query message includes a list of incident information <b>59</b> of potentially different types. Then, in step <b>504</b>, the notifier <b>96</b> executes a lookup of the incident information <b>59</b> in the received message against the threat intelligence data <b>54</b> stored on the datastore <b>135</b> to obtain any stored correlated incident records <b>58</b> having incident information <b>59</b> matching the requested incident information <b>59</b>. In step <b>510</b>, the notifier <b>96</b> determines if any matching correlated incident records <b>58</b> were found. If this statement is true, the method transitions to step <b>512</b>. Otherwise, the method terminates at step <b>516</b>.
In step <b>512</b>, the notifier <b>96</b> filters the matching correlated incident records <b>58</b> in accordance with the sharing and usage information <b>144</b>-<b>5</b> included within the metadata <b>56</b> of each matching correlated incident record <b>58</b>. The notifier <b>96</b>, in step <b>514</b>, sends a reply message to the requesting incident manger <b>102</b> that includes contents of the correlated incident records <b>58</b> not discarded from the filter operation executed in step <b>512</b>. The method then terminates at step <b>516</b>.
<figref idref="DRAWINGS">FIG. 5B</figref> shows a method for an exemplary request issued by an incident manager <b>102</b> to the server system <b>190</b>, for trends data <b>50</b> of the threat intelligence data <b>54</b> over a specified time period.
In step <b>530</b>, the notifier <b>96</b> receives a query message from an incident manager <b>102</b> to obtain trends data <b>50</b> for a specified time period (e.g. within last 24 hours). Then, in step <b>532</b>, the notifier <b>96</b> executes a lookup of the threat intelligence data <b>54</b> for its trends data <b>50</b>, for the specified time period. In step <b>534</b>, the notifier <b>96</b> determines if any trends data <b>50</b> for the specified time period were found. If this statement is true, the method transitions to step <b>536</b> to continue processing. Otherwise, the method terminates at step <b>540</b>.
In step <b>536</b>, the notifier <b>96</b> filters the trends data <b>50</b> in accordance with the sharing and usage information <b>144</b>-<b>6</b> within the trends data <b>50</b>. According to step <b>538</b>, the notifier <b>96</b> sends a reply message to the requesting incident manager <b>102</b>, where the reply message includes contents of the trends data <b>50</b> not discarded from the filter operation executed in step <b>536</b>. The method terminates at step <b>540</b>.
While this invention has been particularly shown and described with references to preferred embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the scope of the invention encompassed by the appended claims.
Contents4
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both waysCites: the store holds 43 of 44
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2007180490A1 | Cites | United States of America | Search report |
| US2010325685A1 | Cites | United States of America | Search report |
| US2013124223A1 | Cites | United States of America | Applicant |
| US2013332590A1 | Cites | United States of America | Applicant |
| US2014278664A1 | Cites | United States of America | Applicant |
| US2014304822A1 | Cites | United States of America | Applicant |
| US2015113663A1 | Cites | United States of America | Applicant |
| US2015235164A1 | Cites | United States of America | Applicant |
| US2015242625A1 | Cites | United States of America | Applicant |
| US2015244681A1 | Cites | United States of America | Search report |
| US2016021133A1 | Cites | United States of America | Applicant |
| US2016072836A1 | Cites | United States of America | Applicant |
| US2016127394A1 | Cites | United States of America | Applicant |
| US6678827B1 | Cites | United States of America | Applicant |
| US7376969B1 | Cites | United States of America | Search report |
| US7877804B2 | Cites | United States of America | Applicant |
| US8032557B1 | Cites | United States of America | Applicant |
| US8244777B1 | Cites | United States of America | Applicant |
| US8510446B1 | Cites | United States of America | Search report |
| US8661062B1 | Cites | United States of America | Applicant |
| US8707445B2 | Cites | United States of America | Applicant |
| US8763133B2 | Cites | United States of America | Applicant |
| US8782784B1 | Cites | United States of America | Applicant |
| US8880682B2 | Cites | United States of America | Applicant |
| US9069930B1 | Cites | United States of America | Applicant |
| US9075668B1 | Cites | United States of America | Applicant |
| US9083734B1 | Cites | United States of America | Applicant |
| US9152706B1 | Cites | United States of America | Applicant |
| US9215270B2 | Cites | United States of America | Applicant |
| US9258321B2 | Cites | United States of America | Applicant |
| US20070180490A1 | Cites | United States of America | Search report |
| US20100325685A1 | Cites | United States of America | Search report |
| US20130124223A1 | Cites | United States of America | Applicant |
| US20130332590A1 | Cites | United States of America | Applicant |
| US20140278664A1 | Cites | United States of America | Applicant |
| US20140304822A1 | Cites | United States of America | Applicant |
| US20150113663A1 | Cites | United States of America | Applicant |
| US20150235164A1 | Cites | United States of America | Applicant |
| US20150242625A1 | Cites | United States of America | Applicant |
| US20150244681A1 | Cites | United States of America | Search report |
| US20160021133A1 | Cites | United States of America | Applicant |
| US20160072836A1 | Cites | United States of America | Applicant |
| US20160127394A1 | Cites | United States of America | Applicant |
| Arbor Networks Peakflow X_eng_0, NCERT-Lab-Pubdoc-2011-12-003, Version 1.00, Croatian Academic and Research Network. Twenty-six pages (2011). | Non-patent | – | Applicant |
| BlackStratus SIEMStorm, “Rapidly identify and resolve threats, . . . ” www.blackstratus.com, 2012. Four pages. | Non-patent | – | Applicant |
| Domino Project Management, “Track and Control Projects with Lotus Notes,” www.trackersuite.com/index, 2013. Two pages. | Non-patent | – | Applicant |
| HP ArcSight Express, “World-Class Protection for the Mid-Size Organization,” www.arcsight.com, 2010. Six pages. | Non-patent | – | Applicant |
| Janet Csirt, “RTIR incident handling work-flow,” Janet (UK) WI/JCSIRT/002, jisc.ac.uk, 2011. Eighteen pages. | Non-patent | – | Applicant |
| Jarocki, J., “Orion Incident Response Live CD,” 2010, Sans Institute, https://www.sans.org. Forty-five pages. | Non-patent | – | Applicant |
| Khurana, H. et al., “Palantir: A Framework for Collaborative Incident Response and Investigation,” IDtrust, 2009. Fourteen pages. | Non-patent | – | Applicant |
| QRadar Administration Guide, http://www.q1labs.com, May 2012. 318 pages. | Non-patent | – | Applicant |
| QRadar Users Guide, http://www.q1labs.com, May 2012. 396 pages. | Non-patent | – | Applicant |
| Reddy, K. et al., “The architecture of a digital forensic readiness management system,” Computers & Security 32 (2013) 73-89. Seventeen pages. | Non-patent | – | Applicant |
| Swift, D., “A Practical Application of SIM/SEM/SIEM Automating Threat Identification,” 2006, SANS Institute 2007. Forty-one pages. | Non-patent | – | Applicant |
| West-Brown, M. et al., “Handbook for Computer Security Incident Response Teams (CSIRTs),” 2nd Edition, Apr. 2003. 223 pages. | Non-patent | – | Applicant |
| U.S. Appl. No. 14/839,304, filed Aug. 28, 2015, entitled “Incident Response Bus for Data Security Incidents.” Specification and drawings, twenty-four pages. | Non-patent | – | Applicant |
| Arbor Networks Peakflow X_eng_0, NCERT-Lab-Pubdoc-2011-12-003, Version 1.00, Croatian Academic and Research Network. Twenty-six pages (2011). | Non-patent | – | Applicant |
| BlackStratus SIEMStorm, “Rapidly identify and resolve threats, . . . ” www.blackstratus.com, 2012. Four pages. | Non-patent | – | Applicant |
| Domino Project Management, “Track and Control Projects with Lotus Notes,” www.trackersuite.com/index, 2013. Two pages. | Non-patent | – | Applicant |
| HP ArcSight Express, “World-Class Protection for the Mid-Size Organization,” www.arcsight.com, 2010. Six pages. | Non-patent | – | Applicant |
| Janet Csirt, “RTIR incident handling work-flow,” Janet (UK) WI/JCSIRT/002, jisc.ac.uk, 2011. Eighteen pages. | Non-patent | – | Applicant |
| Jarocki, J., “Orion Incident Response Live CD,” 2010, Sans Institute, https://www.sans.org. Forty-five pages. | Non-patent | – | Applicant |
| Khurana, H. et al., “Palantir: A Framework for Collaborative Incident Response and Investigation,” IDtrust, 2009. Fourteen pages. | Non-patent | – | Applicant |
| QRadar Administration Guide, http://www.q1labs.com, May 2012. 318 pages. | Non-patent | – | Applicant |
| QRadar Users Guide, http://www.q1labs.com, May 2012. 396 pages. | Non-patent | – | Applicant |
| Reddy, K. et al., “The architecture of a digital forensic readiness management system,” Computers & Security 32 (2013) 73-89. Seventeen pages. | Non-patent | – | Applicant |
| Swift, D., “A Practical Application of SIM/SEM/SIEM Automating Threat Identification,” 2006, SANS Institute 2007. Forty-one pages. | Non-patent | – | Applicant |
| West-Brown, M. et al., “Handbook for Computer Security Incident Response Teams (CSIRTs),” 2nd Edition, Apr. 2003. 223 pages. | Non-patent | – | Applicant |
| U.S. Appl. No. 14/839,304, filed Aug. 28, 2015, entitled “Incident Response Bus for Data Security Incidents.” Specification and drawings, twenty-four pages. | Non-patent | – | Applicant |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201514981266 | United States of America | A | |
| US201514981266 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| US2017187742A1 | United States of America | A1 | |
| US10348754B2This record | United States of America | B2 |
82 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Correspondence Address ChangeC.ADB | C.ADB | |
| Surcharge for Late Payment, Large EntityM1554 | M1554 | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Correspondence Address ChangeC.AD | C.AD | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Email NotificationEML_NTR | EML_NTR | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing Receipt - CorrectedFLRCPT.C | FLRCPT.C | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Pre-Exam NoticeMPEN | MPEN | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Application Is Now CompleteCOMP | COMP | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| Applicant Has Filed a Verified Statement of Small Entity Status in Compliance with 37 CFR 1.27SMAL | SMAL | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| PTO/SB/69-Authorize EPO Access to Search ResultsSREXR141 | SREXR141 | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedureSURCHARGE FOR LATE PAYMENT, LARGE ENTITY (ORIGINAL EVENT CODE: M1554); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| Fee payment procedureENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT RECEIVEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 10348754
- Publication, DOCDB
- 10348754
- Publication, EPODOC
- US10348754
- Application
- 14981266
- Application, DOCDB
- 201514981266
- Application, EPODOC
- US201514981266
Titles
- English
- Data security incident correlation and dissemination system and method
Patent term adjustment
- A delay
- +221 daysthe office missed an examination deadline
- B delay
- +24 dayspendency past three years
- Applicant delay
- −32 days
- Net adjustment
- 213 days
Classification
- CPC, 3
- H04L63/1433
- H04L63/1441
- H04L63/20
- IPC, 1
- H04L29 06
- USPC, 1
- 709224000